Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Blue Pill threat dead? … That's wishful thinking

By Ellen Messmer , Network World , 08/08/2007
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

Joanna Rutkowska, the renowned rootkit researcher at Invisible Things Lab based in Poland, has ignited keen interest in virtualization-based malware with her creation called Blue Pill. Last year at the Black Hat conference she gave a presentation on Blue Pill, and at last week’s Black Hat 2007, she announced she is making the New Blue Pill, which, among other things, can run tens of Blue Pills inside each other, available for research purposes.

Taking up the challenge to try and detect stealthy rootkits, researchers from Symantec, Root Lab, and Matasano, which gave their own presentation at Black Hat entitled “Don’t Tell Joanna, the Virtualized Rootkit is Dead,” are aiming to prove they can detect Blue Pill and any other virtualized rootkit with software they’ve collaborated on called Samsara. But no one is declaring victory yet in detecting Blue Pill. In the following essay, Rutkowska shares some observations about things not easily seen. --  Ellen Messmer

By Joanna Rutkowska, Invisible Things Lab

Since the Black Hat conference last year, when I presented the first hardware virtualization-based malware, code-named “Blue Pill,” the amazing debate has been going on. Several security researchers decided to prove that the virtualization malware threat is non-existent. Some went even as far as to announce that the “virtualized rootkit is dead. Interestingly, none of those researchers have presented any solution to be used for either virtualization malware prevention or detection.

First, it turned out that the “blue pill killers” confused virtualization detection with virtualization rootkits detection. Wait a second – but isn’t that the same thing, you might ask? After all, virtualization-based rootkits need to make use of virtualization, so by detecting (unexpected) virtualization we detect the virtualization-based malware as well, right? Well, not quite – it’s a bit like saying that every program that makes use of networking is a botnet agent, just because botnet agents need to use networking.

As hardware virtualization technology gets more and more widespread, many machines will be running with virtualization mode enabled, both servers and desktops, no matter whether “bluepilled” or not. In that case, blue pill-like malware will not need to take any special efforts to pretend that virtualization is not enabled, as it’s actually expected that virtualization is being used for some legitimate purposes. This means the rootkit code can be greatly simplified.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed